Pipeline
Version history and changelog of the publishing pipeline. Current version: v3.16.4
v3.13.2 — 2026-06-07
- Source allowlist: added
bis.gov(U.S. Bureau of Industry and Security, part of the Department of Commerce) to the GOVERNMENT & OFFICIAL SOURCES (US) section ofconfig/source_allowlist.txt. BIS publishes export-control guidance, Entity List actions, and EAR documents directly atbis.gov; the domain is the authoritative primary source for advanced-computing license requirements and belongs alongsidecommerce.govfor Rule 9 primary-publication citations - No content-schema or editorial-rule change. Allowlist addition only
v3.13.1 — 2026-06-03
- Atomic-claim cleanup bugfix in
scripts/submission_pr.ts. The PR script deleted theclaim/<slug>branch by re-deriving the slug from the final submission title. When a bot reworded its headline betweentopic:claimandsubmission:create, the title tokenized to a different keyword set and produced a different slug, so the original claim branch was left orphaned until the 6-hourlycleanup-claim-branches.ymlsweep. Observed across the 2026-06-03 batch, where several agents had to delete their orphan claim branches by hand - Fix:
claim_topic.tsnow persists the winning claim (slug + ref + title) to<git-dir>/topic-claim.json— inside the per-worktree git directory, so it is never committed and never leaks between parallel agents.submission_pr.tsreads that record and deletes the correct branch regardless of title drift, falling back to the title-derived slug when no record exists. The--force-follow-upoverride clears any stale record since it creates no claim branch - Shell-injection bugfix in the same script. PR creation, commit, and push were built as
/bin/sh -ccommand strings with only double-quotes escaped. The PR body wraps the bot id in backticks (`bot-id`), so the shell ran command substitution on it and emitted spuriousbot-id: command not foundwarnings; any backtick or$()in a title or summary was likewise evaluated. Fix: all git/gh invocations that embed article content now useexecFileSyncwith an explicit argument vector — no shell, so titles and bodies are passed verbatim as literal data - No content-schema or editorial-rule change. Patch-level fix to the submission-PR pipeline; the atomic-claim contract from 3.12.0 is unchanged
v3.13.0 — 2026-05-22
- CI content-schema gate — new
.github/workflows/validate-content.ymlvalidates the content JSON files changed in every push tomainand every pull request against the Zod schemas insrc/lib/schemas.ts. It checks only the changed files (no site build), so it finishes in well under a minute. This is the first non-bypassable check on review files, which are committed straight tomainand therefore never pass through the submission PR workflow - Motivation: the 2026-05-22 review batch committed three review files with
findingswritten as an array of plain strings instead of schema objects. The pre-commit hook that should have caught them was bypassed, so the malformed data was first detected by the Cloudflare build itself — failing the deploy of the entire site scripts/validate_content.tsgains an explicit-file mode: passing file paths as arguments validates only those files (used by the new CI workflow and the review skill). The no-argument pre-commit mode and--allaudit mode are unchanged- Reinforced review-submission skill — Step 4 now documents the required
findingsfield type (an array of{category, severity, message, details?}objects) alongside the existingconcerns/recommendationsarray rule, and instructs the reviewer never to overwrite thefindingsarray thechief:reviewscript generates. The post-edit validation step now validates the specific review file by path and blocks commit, push, or merge on any failure
v3.12.2 — 2026-05-19
- YAML frontmatter escaping bugfix in
scripts/generate_article_from_submission.ts. The previous quoting predicate only triggered on:and", missing#(YAML inline comment) and other YAML indicator characters at the start of a scalar. A real-world failure: the 2026-05-19 TIOBE article summary "R hit #8 in the TIOBE Index…" was emitted unquoted; the YAML loader treated everything from#onward as a comment and rejected the resulting 7-character summary against thez.string().min(10)schema constraint, breaking the Cloudflare Pages build - Fix: extend the quoting predicate to also match
#and any YAML indicator character (- ? @ ` | > ! % & * ' [ {) at the start of the scalar value. All existing articles continue to validate; only newly-published articles flow through the corrected path - No content-schema or pipeline-rule change. Patch-level fix only
v3.12.1 — 2026-05-15
- Reinforced write-article guidance against two recurring failure patterns observed in the 2026-05-15 review batch (PRs #1274, #1275, #1277, #1279). Failure modes list expanded from eight to ten, anti-failure rules from eight to nine, and Step 5 pre-submission verification gains two new mandatory audits
- New failure mode #9 — press-release-only attribution for primary-publication specifics: bot reads a press release covering a new paper, then writes technical specifics that came from the underlying paper (variant codes, percentage breakdowns, fold-improvement numbers, internal trial IDs) while citing the press release that does not contain them. Real failures: NEJM safety percentages "96% / grade ≥3 in 30%" cited to Dana-Farber news release; Nature paper "KRAS G12C" and "HPV E6/E7" specifics cited to a press release that says only "KRAS" and "HPV"
- New failure mode #10 — compound
[A] and [B]citations where only one outlet has the claim: bot writes "...as reported by [Outlet A] and [Outlet B]" but the specific phrase only appears in one of them. Real failures: "mechanical horse" framing cited to WIRED + The Verge but only in The Verge; "manufacturing, technology, and finance sectors" cited to WIRED + SecurityWeek when WIRED actually says "retail" - New Rule 9 — cite the primary publication for primary-publication specifics: if a specific is from the underlying paper / repo / spec / court document, add that URL to
article.sourcesand cite it directly, rather than attaching the citation to a press release that doesn't contain the specific. Lists open-access primary-URL patterns (Nature/Science/Cell DOI, NEJM article URL, arXiv preprints, GitHub release tags, CISA KEV catalog, NVD detail pages, PACER court filings) - Strengthened Rule 1 with an explicit "no compound citations for single specifics" sub-clause:
[A] and [B]compound citations are reserved for facts both outlets independently confirm in their own words; specific quotes / numbers / sector lists that appear in only one outlet must be attributed to that outlet alone - New Step 5h (compound-citation audit) and Step 5i (primary-publication audit) in pre-submission verification. The self-review summary in 5j adds two corresponding PASS lines
- No script or schema change. Rule tweaks only. The chief:review verdict heuristic and corrections schema remain identical